Grafana Labs is looking for a Security Assurance Engineer to join their GRC engineering team to build an automated, data-driven security system with defense-in-depth and self-healing capabilities to support their cloud-native, remote-first organization.
Requirements
- Solid experience with at least one programming language. We primarily use Go, TypeScript, and Python but most languages translate well. You will take a code screen.
- Knowledge of using and securing containerized, cloud-native applications, ideally with Kubernetes. Experience with multiple cloud providers is a strong plus.
- Experience in automating security compliance processes using tools, scripts, and frameworks while enabling developer and employee workflows.
- Some understanding of industry-recognized security frameworks, standards, and certifications, such as ISO 27001, SOC 2, PCI DSS, NIST, or GDPR.
- Working knowledge of Grafana Labs OSS projects and products.
- Experience in using observability tooling to solve security problems.
- Experience securing large-scale distributed systems running in public clouds
Responsibilities
- Be a technical contributor on our assurance team covering a range of areas, including certifications, application, build, cloud, and supply chain security, and internal security tooling development
- Develop, implement, and maintain highly automated security assurance programs to ensure compliance with organizational and regulatory requirements (e.g., ISO 27001, SOC 2, GDPR, NIST, PCI-DSS, TISAX, whatever else our customers eventually throw at us)
- Develop systems, automations, and methods of security observability to push the GRC engineering organization beyond just meeting certification requirements
- Deploy security and compliance checks in an employee-enabling way (guardrails and paved roads) in their daily workflows and build pipelines
- Collaborate with cross-functional teams to integrate security controls into the software development lifecycle and operational processes.
- Respond to customer security issues, security alerts, and potential incidents
Other
- This is a remote position. We are looking for candidates in Eastern US time zones.
- Strong interpersonal skills. Some experience collaborating (and negotiating) with peers, stakeholders, auditors, and customers.
- A degree in Computer Science, Information Security, or related field (or equivalent experience).
- Experience working with OSS communities
- In-person onboarding